Critical severity9.8NVD Advisory· Published Jul 8, 2019· Updated Jun 17, 2026
CVE-2019-13354
CVE-2019-13354
Description
The strong_password gem 0.0.7 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. The current version, without this backdoor, is 0.0.6.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
strong_passwordRubyGems | >= 0.0.7, < 0.0.8 | 0.0.8 |
Affected products
3- Ruby/strong_passworddescription
- cpe:2.3:a:strong_password_project:strong_password:0.0.7:*:*:*:*:ruby:*:*
Patches
Vulnerability mechanics
References
8- benjamin-bouchet.com/blog/vulnerabilite-dans-la-gem-strong_password-0-0-7/nvdThird Party Advisory
- github.com/advisories/GHSA-5h5r-ffc4-c455ghsaADVISORY
- github.com/bdmac/strong_password/releasesnvdRelease NotesThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2019-13354ghsaADVISORY
- rubygems.org/gems/strong_password/versionsnvdRelease NotesThird Party AdvisoryWEB
- withatwist.dev/strong-password-rubygem-hijacked.htmlnvdThird Party AdvisoryWEB
- benjamin-bouchet.com/blog/vulnerabilite-dans-la-gem-strong_password-0-0-7ghsaWEB
- github.com/rubysec/ruby-advisory-db/blob/master/gems/strong_password/CVE-2019-13354.ymlghsaWEB
News mentions
0No linked articles in our index yet.